7.2

CVE-2021-1543

Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the following: Hijack a user session Execute arbitrary commands as a root user on the underlying operating system Conduct a cross-site scripting (XSS) attack Conduct an HTML injection attack For more information about these vulnerabilities, see the Details section of this advisory.

Data is provided by the National Vulnerability Database (NVD)
CiscoSf220-24 Firmware Version < 1.2.0.6
   CiscoSf220-24 Version-
CiscoSf220-24p Firmware Version < 1.2.0.6
   CiscoSf220-24p Version-
CiscoSf220-48 Firmware Version < 1.2.0.6
   CiscoSf220-48 Version-
CiscoSf220-48p Firmware Version < 1.2.0.6
   CiscoSf220-48p Version-
CiscoSg220-26 Firmware Version < 1.2.0.6
   CiscoSg220-26 Version-
CiscoSg220-26p Firmware Version < 1.2.0.6
   CiscoSg220-26p Version-
CiscoSg220-28mp Firmware Version < 1.2.0.6
   CiscoSg220-28mp Version-
CiscoSg220-50 Firmware Version < 1.2.0.6
   CiscoSg220-50 Version-
CiscoSg220-50p Firmware Version < 1.2.0.6
   CiscoSg220-50p Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.28% 0.507
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
psirt@cisco.com 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.